Incident Response Analyst:

Fortinet
Tel Aviv
Workplace: HybridFull timeFunction: Solutions Engineering & Sales EngineeringExperience: 3+ yearsSkills: ["Written communication","Verbal communication","Teamwork","Proactive","Ownership"]

Investigate and respond to workspace security incidents across email, browser security, and perimeter security domains. Handle customer investigation requests, perform phishing analysis and threat hunting, and build detections for new attack tactics and campaigns. Collaborate with development and research teams to deliver incident-driven insights and detection engines. Communicate findings through professional blog posts while working rotating shifts within a 24/7 operation.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Fortinet
Fortinet
5 days ago

Incident Response Analyst:

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Investigate and respond to workspace security incidents across email, browser security, and perimeter security domains. Handle customer investigation requests, perform phishing analysis and threat hunting, and build detections for new attack tactics and campaigns. Collaborate with development and research teams to deliver incident-driven insights and detection engines. Communicate findings through professional blog posts while working rotating shifts within a 24/7 operation.
Location: Tel Aviv
Workplace: Hybrid
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Investigate and respond to workspace security incidents across email, browser security, and perimeter security domains.
  • •Manage investigation requests submitted by customers.
  • •Perform targeted phishing analysis and investigate new attack campaigns.
  • •Conduct threat hunting using attack patterns, behaviors, and indicators, then build and improve detections for new attack types and trends.
  • •Collaborate with development and research teams to create incident-driven insights and detection engines; write incident-focused blog posts and work rotating 24/7 shifts.

Key Requirements

  • •At least 3 years of experience in an Incident Response or Security Operations role.
  • •Strong understanding of attack vectors including phishing, BEC, email spoofing/impersonation, malware, and ATO.
  • •Knowledge of email protocols and security concepts such as SMTP, SPF/DKIM/DMARC, email headers, and authentication methods.
  • •Strong querying skills using SQL, SPL, KQL, or AQL.
  • •Familiarity with static and dynamic techniques and the ability to read and analyze malicious scripts (e.g., Python, JavaScript, Visual Basic).
Experience:3+ yearsCybersecurityIncident responseSecurity operations
Skills:Written communicationVerbal communicationTeamworkProactiveOwnership
Languages:English
Tech Stack:SQLSPLKQLAQLPythonJavaScriptVisual BasicSMTPSPFDKIMDMARCEmail headersPhishingThreat huntingStatic analysisDynamic analysis

Company Brief

Fortinet
Provides enterprise cybersecurity solutions including data protection, cloud security, network security, and user and entity behavior analytics to help organizations prevent insider threats, secure cloud and on-premises environments, and enforce data loss prevention policies.
Industry: Cybersecurity
Company Size: Enterprise (1,001+ employees)
Growth: Established Company
Funding: Private Equity Backed
Headquarters: Austin, United States
Founded: 1994
WebsiteLinkedIn